πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26.1K subscribers
89.3K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΅οΈβ€β™‚οΈ Okta Fixes Auth Bypass Bug After 3-Month Lull πŸ•΅οΈβ€β™‚οΈ

The bug affected accounts with 52character user names, and had several preconditions that needed to be met in order to be exploited.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ OWASP Beefs Up GenAI Security Guidance Amid Growing Deepfakes πŸ•΅οΈβ€β™‚οΈ

As businesses worry over deepfake scams and other AI attacks, organizations are adding guidance for cybersecurity teams on how to detect, and respond to, nextgeneration threats. That includes Exabeam, which was recently targeted by a deepfaked job candidate.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
🦿 Software Makers Encouraged to Stop Using C/C++ by 2026 🦿

The Cybersecurity and Infrastructure Security Agency and Federal Bureau of Investigation assert that C, C, and other memoryunsafe languages contribute to potential security breaches.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ APT36 Refines Tools in Attacks on Indian Targets πŸ•΅οΈβ€β™‚οΈ

The Pakistanbased advanced persistent threat actor has been carrying on a cyberespionage campaign targeting organizations on the subcontinent for more than a decade, and it's now using a new and improved "ElizaRAT" malware.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Iranian APT Group Targets IP Cameras, Extends Attacks Beyond Israel πŸ•΅οΈβ€β™‚οΈ

The Iranlinked group Emennet Pasargad aims to undermine public confidence in Israeli and Western nations by using hackandleak campaigns and disrupting government services, including elections.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ–‹οΈ Malware Campaign Uses Ethereum Smart Contracts to Control npm Typosquat Packages πŸ–‹οΈ

An ongoing campaign is targeting npm developers with hundreds of typosquat versions of their legitimate counterparts in an attempt to trick them into running crossplatform malware. The attack is notable for utilizing Ethereum smart contracts for commandandcontrol C2 server address distribution, according to independent findings from Checkmarx, Phylum, and Socket published over the past few.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
πŸ–‹οΈ Canadian Suspect Arrested Over Snowflake Data Breach and Extortion Attacks πŸ–‹οΈ

Canadian law enforcement authorities have arrested an individual who is suspected to have conducted a series of hacks stemming from the breach of cloud data warehousing platform Snowflake earlier this year. The individual in question, Alexander "Connor" Moucka aka Judische and Waifu, was apprehended on October 30, 2024, on the basis of a provisional arrest warrant, following a request by the.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Google Warns of Actively Exploited CVE-2024-43093 Vulnerability in Android System πŸ–‹οΈ

Google has warned that a security flaw impacting its Android operating system has come under active exploitation in the wild. The vulnerability, tracked as CVE202443093, has been described as a privilege escalation flaw in the Android Framework component that could result in unauthorized access to "Androiddata," "Androidobb," and "Androidsandbox" directories and its subdirectories,.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘½ Hackers Strike at Heart of Italian Government πŸ‘½

In a scenario reminiscent of a modernday Italian Job, hackers have allegedly breached Italys national security, exposing confidential data of some of the countrys most prominent political figures. At the heart of the controversy is Nunzio Samuele Calamucci, a 44yearold IT consultant operating from a modest office near Milans iconic.

πŸ“– Read more.

πŸ”— Via "BE3SEC"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘2
πŸ“” Chinese Air Fryers May Be Spying on Consumers, Which? Warns πŸ“”

A Which? report outlines serious privacy concerns with smart device products including air fryers.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Synology Urges Patch for Critical Zero-Click RCE Flaw Affecting Millions of NAS Devices πŸ–‹οΈ

Taiwanese networkattached storage NAS appliance maker Synology has addressed a critical security flaw impacting DiskStation and BeePhotos that could lead to remote code execution. Tracked as CVE202410443 and dubbed RISKSTATION by Midnight Blue, the zeroday flaw was demonstrated at the Pwn2Own Ireland 2024 hacking contest by security researcher Rick de Jager. RISKSTATION is an ".

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“’ Five ways cyber criminals target healthcare and how to stop them πŸ“’

Medical institutions are among the top targets for threat actors, here five major threats facing the healthcare sector and what organizations can do to stay secure.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
❀2
πŸ“’ Google’s Big Sleep AI model just found a zero-day vulnerability in the wild β€” but don’t hold your breath for game-changing AI bug hunting tools any time soon πŸ“’

Google clarified it was the first undiscovered memory safety bug to be flagged by an AI agent, touting this as a significant step in using AI for vulnerability research.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
πŸ“’ Schneider Electric confirms breach after hacker claims to have 40GB of stolen data πŸ“’

A hacker claimed to have stolen 400,000 rows of user data from Schneider Electric and took to social media to taunt the French multinational.

πŸ“– Read more.

πŸ”— Via "ITPro"

----------
πŸ‘οΈ Seen on @cibsecurity
❀1
πŸ•΅οΈβ€β™‚οΈ Docusign API Abused in Widescale, Novel Invoice Attack πŸ•΅οΈβ€β™‚οΈ

Attackers are exploiting the "Envelopes create API" of the enormously popular documentsigning service to flood corporate inboxes with convincing phishing emails aimed at defrauding organizations. It's an unusual attack vector with a high success rate.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Oh, the Humanity! How to Make Humans Part of Cybersecurity Design πŸ•΅οΈβ€β™‚οΈ

Government and industry want to jumpstart the conversation around "humancentric cybersecurity" to boost the usability and effectiveness of security products and services.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ How to Win at Cyber by Influencing People πŸ•΅οΈβ€β™‚οΈ

Zero trust is a mature approach that will improve your organization's security.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Dark Reading Confidential: Quantum Has Landed, So Now What? πŸ•΅οΈβ€β™‚οΈ

Episode 4 NIST's new postquantum cryptography standards are here, so what comes next? This episode of Dark Reading Confidential digs the world of quantum computing from a cybersecurity practitioner's point of view with guests Matthew McFadden, vice president, Cyber, General Dynamics Information Technology GDIT and Thomas Scanlon, professor, Heinz College, Carnegie Mellon University.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ On Election Day, Disinformation Worries Security Pros the Most πŸ•΅οΈβ€β™‚οΈ

A Dark Reading poll reveals widespread concern over disinformation about election integrity and voter fraud, even as Russia steps up deepfake attacks meant to sow distrust in the voting process among the electorate.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 VMware Explore Barcelona 2024: Tanzu Platform 10 Enters General Availability 🦿

About a year after Broadcoms acquisition of VMware, the company released VMware Tanzu Data Services to make connections to some thirdparty data engines easier.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity
🦿 The 7 Best Encryption Software Choices for 2024 🦿

This is a comprehensive list of the best encryption software and tools, covering their features, pricing and more. Use this guide to determine your best fit.

πŸ“– Read more.

πŸ”— Via "Tech Republic"

----------
πŸ‘οΈ Seen on @cibsecurity